Security GRC Specialist, IT/Security Risk Management
Wealthsimple
In this role, you'll have the opportunity to Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
Contribute to the development and maintenance of risk policies, standards, and procedures
Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
What you'll bring
3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
Experience maintaining risk registers and supporting risk assessment processes
Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
Comfortable working cross-functionally with both technical and non-technical stakeholders
Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
Self-starter who can operate independently, manage competing priorities, and drive work to completion
Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
Contribute to the development and maintenance of risk policies, standards, and procedures
Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
Experience maintaining risk registers and supporting risk assessment processes
Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
Comfortable working cross-functionally with both technical and non-technical stakeholders
Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
Self-starter who can operate independently, manage competing priorities, and drive work to completion
Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
$102.5k - $187.9k
...604Salary: $102,500 - $187,900Job Function: Risk ConsultingEmployer: EY Global ServicesApply... ...across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand risk management challenges and can support improved business...SuggestedSummer holidayFlexible hoursShift work- ResponsibilitiesThe Manager, IAM Engineering is responsible for leading... ..., ensuring solutions are secure, scalable, resilient, and aligned... ...with Security Operations, GRC, Infrastructure, and application... ...solutions that meet business needs.Risk, Compliance & Control...SuggestedRemote work
$65k - $70k
...be a public research university. Job Summary The IT Security Analyst supports the university's governance, risk, and compliance (GRC) program with a primary focus on accessibility compliance, third-party risk management, and operational security support. The IT...SuggestedFor contractorsWork at officeFlexible hoursWeekend workAfternoon shift- The Department of Economic Security, Division of Technology Services is seeking an IT Security Analyst (GRC) contractor to support the Governance, Risk and Compliance team and collaborate with business units to understand reporting, data, and product needs. The role involves...SuggestedRemote jobFor contractorsWork from homeFlexible hours
- ...Security Administration and Operations This team is tasked with providing endpoint... ...and security configuration management to the enterprise. Security Administration... ...configuration policies. Provide support to Risk management and IT Security Audit teams assisting in...SuggestedRemote workWeekend workAfternoon shift
$29.94 - $32.04 per hour
...The IT Security Analyst will assist the Enterprise IT Security Risk Management Team in monitoring, analyzing, and responding to security events to safeguard the confidentiality, integrity, and availability of our healthcare systems and data. This position will work...Full timeWork at officeMonday to Friday- ...Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical... ...platform and Jira. Partner with engineering and IT teams to close control gaps and drive...Remote jobWork at officeLocal area
- S R INTERNATIONAL INC is seeking an IT Security Analyst (GRC) contractor for the State of Arizona DES - DTS. This role involves governance, risk and compliance activities, communicating with business units, defining requirements, developing data models and data flows,...Remote jobFor contractors
- A leading media and entertainment company is looking for an experienced SAP Security professional in New York. This role involves managing user security tasks across various SAP environments, ensuring compliance with internal and external standards including SOX, while...Remote work
$152.7k - $294k
...world.The Global Information Security Strategist is a senior role responsible... ...business demands and cyber risks.Key Responsibilities:Strategic... ...leadership and stakeholder management skills. Proven ability to lead... ...diverse teams (security, IT, and business) through influence...Summer holidayLocal areaFlexible hoursShift work$125.1k - $225.2k
...Description:Parsons is looking for an amazingly talented Security Specialist - Risk Management Framework to join our team! In this role you will get to... ...system, contractors are required to complete annual refresher IT Security Awareness training as well as additional...Full timeFor contractorsWork at officeRemote workFlexible hours- ...Join to apply for the 1.20. IT Security Analyst role at Focused HR Solutions . 100% onsite in Richmond, VA. No remote work is allowed... ...Information Security program by providing cybersecurity, risk management, IT infrastructure services and IT governance by working with...Contract workWork at officeRemote work
$175k - $225k
...infrastructure at scale.The Director of IT, Security & Compliance serves as the senior leader... ...working with the developers as customers.Manage relationships with external vendors,... ...required), incident response activities, and risk management initiatives, with a pragmatic...Remote work$600 per month
...October 1, 2026* Job Summary As Corporate Security Manager, this position defines and directly... ...public record information. Security and Risk Assessments Strategically assesses and mitigates... ...renewal dates. Supports Human Resources IT & and Security, Legal, and Finance in...Contract workLocal areaRemote workShift workNight shift- ...into reality.We AreAccenture Security helps organizations prepare, protect... ...from within. We blend risk strategy, digital identity, cyber... ...defense, application security and managed service solutions to rethink... ...of experience Enterprise IT security risk assessments and...Full timeWork experience placementLive inWork at officeLocal areaRemote work
- ...pastries to employeesJob DescriptionThe Director of (Cyber) Security Architecture and Engineering is a cyber leadership role responsible... ...business strategy, technology transformation, and enterprise risk management objectives. This role provides strategic and hands-on...Live inWork at officeWork from homeFlexible hours
- ...Ncdit - Security Specialist- Mid LevelLocation: 221 E Lane Street, Raleigh NC 27601Client: State of NCType: C2C/W2The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and possess knowledge of HIPAA and NIST privacy...Full timeRemote work
$109.37k - $123.04k
...Summary:We are seeking a highly skilled and motivated Senior Manager, IT Security Operations to join our team. As the Senior Manager, IT... ...align with overall business objectives.Communicate security risks and recommendations to management and relevant stakeholders....Full timeWork experience placementWork at officeLocal areaRemote work- ...the Team Affirm values security as being critical to... ...success. The Security Risk Management team is evolving beyond... ...) to replace manual GRC work with scalable, code... ...Risk Management Specialist to help scale Affirm's... ..., Legal, Engineering, IT, Compliance, and Privacy...Full time
$130k - $180k
Affirm is hiring a remote candidate for Security Risk Management Specialist II. This is a full time position.... ...coding platforms) to replace manual GRC work with scalable, code-defined workflows... ...Procurement, Legal, Engineering, IT, Compliance, and Privacy on third‑party...Full timeWork at officeRemote workFlexible hours$88.3k - $162.43k
...Technology Organization Info Technology Solutions Department IT Risk Management Dept Location Remote/Hybrid Salary $88,302 - $162,426 Date... ...No; UC Internal Job: No Position Information The Information Security Analyst is responsible for the implementation of the Information...Full timePart timeFor contractorsWork at officeLocal areaRemote workWorldwideWork visa$121 - $194 per hour
...7 year of experience in data security and protectionMust have experience... ...in Data Security Posture Management (DSPM), including the... ...and mitigating data security risks through continuous monitoring... ...with governance standards. The specialist will also be responsible for...Full timeWork at officeLocal areaRemote work1 day per week$99k - $225k
Information Security Risk SpecialistThe Opportunity:As an Information Security Risk Specialist on our team, you will leverage your expertise... ...to ensure effective risk management and cybersecurity resilience... ...experience working in a professional IT environment3+ years of...Full timeContract workPart timeFor contractorsWork at officeLocal areaRemote work$61.9k - $141k
Information Security Risk SpecialistThe Opportunity: Conduct security assessments on DoD cloud environments using the Risk Management Framework (RMF). Assist in providing guidance on policies and procedures to ensure compliance within an accreditation boundary. Implement...Full timeContract workPart timeWork at officeLocal areaRemote work$63.54 - $87.91 per hour
...Information Systems Identity and Access Management Shift: Day (United States of... ...Details Shape and influence security architecture across a large,... ...management, governance, and risk management. Drive secure-by-... ...MN Job Description Manage the IT Security team ensuring system-...Hourly payContract workTemporary workWork at officeRemote workShift workDay shift$72.06k - $107.2k
Security and Emergency Management Specialist Osseo Ind School District 279 Educational Service Center - Maple Grove, Minnesota Open in Google Maps Security... ...and policies which pertain to the security and risk management of all district locations; designing, developing...Full timeLocal areaImmediate startWork visaFlexible hours$40 - $43 per hour
...backgrounds. If you are passionate about intelligence, risk analysis, threat management, executive protection, security operations, or business resiliency, Concentric... ...currently looking to hire a Corporate Security Specialist to join our team embedded with our client in...Currently hiringWork at officeRemote workMonday to FridayShift work- ...in this role:Being a member of IT Cybersecurity Engineering and... ...provide best in class and versatile security services to the enterprises.... ...a People Leader (functional manager), strong candidates will have... ...and evaluating potential risks associated with cloud services...Remote workFlexible hours
- ...engineering, operations management, and technology to... ...response, and the Microsoft security suite. This role... ...to identify potential risks and vulnerabilities relevant... ...performance. Collaborate with IT and other departments... ...tracking tools, GRC platforms, and project...Permanent employmentFull timeContract work
$90k - $115k
...restrictions. Our Senior Security Policy Analyst is... ...ServiceNow to streamline policy management, compliance tracking, and reporting... ...experience in governance, risk, and compliance (GRC) operations, and excels at... ...Like to collaborate with IT, Risk, Compliance, and...Full timeContract workFor contractorsWork at officeLocal areaImmediate startRemote work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security GRC Specialist, IT/Security Risk Management. Be the first to apply!
- security consultant Remote
- security advisor Remote
- senior information security analyst Remote
- cloud security analyst Remote
- entry level security analyst Remote
- physical security specialist Remote
- senior security consultant Remote
- aws security specialist Remote
- security analyst remote Remote
- security analyst intern Remote




